7.8

CVSS3.1

CVE-2025-24928 - libxml2: Stack-based buffer overflow in xmlSnprintfElements of libxml2

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 7:08 p.m.

9.8

CVSS3.1

CVE-2024-57045 -

A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: May 21, 2025, 1:08 p.m.

7.8

CVSS3.1

CVE-2024-56171 - libxml2: Use-After-Free in libxml2

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be use…

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:17 p.m.

7.5

CVSS3.1

CVE-2024-50609 -

An issue was discovered in Fluent Bit 3.1.9. When the OpenTelemetry input plugin is running and listening on an IP address and port, one can send a packet with Content-Length: 0 and it crashes the server. Improper handling of the case when Content-Length is 0 allows a user (with access to the endpo…

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 2:48 p.m.

7.8

CVSS3.1

CVE-2025-21702 - pfifo_tail_enqueue: Drop new packet when sch->limit == 0

In the Linux kernel, the following vulnerability has been resolved: pfifo_tail_enqueue: Drop new packet when sch->limit == 0 Expected behaviour: In case we reach scheduler's limit, pfifo_tail_enqueue() will drop a packet in scheduler's queue and decrease scheduler's qlen by one. Then, pfifo_tail_…

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: April 2, 2026, 8:39 a.m.

9.8

CVSS3.1

CVE-2024-55460 -

A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election System Version v2.0 allows attackers to execute arbitrary code via a crafted input.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: Feb. 19, 2025, 3:15 p.m.

2

CVSS3.1

CVE-2024-57257 -

A stack consumption issue in sqfs_size in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with deep symlink nesting.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

5.9

CVSS3.1

CVE-2025-26466 - Openssh: denial-of-service in openssh

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an…

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: Feb. 10, 2026, 6:16 p.m.

5

CVSS3.1

CVE-2024-57055 -

Server-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potentially call certain services without the necessary access level. This issue is limited to services used by the client (not the general-use JSON services) and requires reverse engineer…

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: Feb. 19, 2025, 9:15 p.m.

5.3

CVSS3.1

CVE-2025-22920 -

A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat when processing tile grid group streams. This can lead to a Denial of Service (DoS).

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: July 13, 2025, 11:07 a.m.
Total resulsts: 343919
Page 6184 of 34,392
Β« previous page Β» next page
Filters